peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

403,746 CVEs 1,739 on KEV 17,300 EPSS ≥ 10% 25,091 with exploits synced 2026-10-10

36,968 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2016-1580 The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when usin… In your normal cycle 9.8 critical 3.5% 2016-05-13
CVE-2024-23724 Ghost through 5.76.0 allows stored XSS, and resultant privilege escalation in which a contributor can take over any account, via an SVG profile pictur… In your normal cycle 9.0 critical 3.5% 2024-02-11
CVE-2026-5524 The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and including… In your normal cycle 9.8 critical 3.5% 2026-07-02
CVE-2019-17509 D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /… In your normal cycle 9.8 critical 3.5% 2019-10-11
CVE-2018-7066 An unauthenticated remote command execution exists in Aruba ClearPass Policy Manager on linked devices. The ClearPass OnConnect feature permits admini… In your normal cycle 9.0 critical 3.5% 2018-12-07
CVE-2005-3056 TWiki allows arbitrary shell command execution via the Include function In your normal cycle 9.8 critical 3.5% 2019-11-01
CVE-2016-0912 EMC Data Domain OS 5.4 through 5.7 before 5.7.2.0 allows remote authenticated users to bypass intended password-change restrictions by leveraging acce… In your normal cycle 9.8 critical 3.5% 2016-06-19
CVE-2021-27464 The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This… In your normal cycle 10.0 critical 3.5% 2022-03-23
CVE-2012-1301 The FeedProxy.aspx script in Umbraco 4.7.0 allows remote attackers to proxy requests on their behalf via the "url" parameter. In your normal cycle 9.8 critical 3.5% 2017-04-13
CVE-2023-23415 Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability In your normal cycle 9.8 critical 3.5% 2023-03-14
CVE-2018-11779 In Apache Storm versions 1.1.0 to 1.2.2, when the user is using the storm-kafka-client or storm-kafka modules, it is possible to cause the Storm UI da… In your normal cycle 9.8 critical 3.5% 2019-07-26
CVE-2020-0654 A security feature bypass vulnerability exists in Microsoft OneDrive App for Android.This could allow an attacker to bypass the passcode or fingerprin… In your normal cycle 9.1 critical 3.5% 2020-01-14
CVE-2017-12902 The Zephyr parser in tcpdump before 4.9.2 has a buffer over-read in print-zephyr.c, several functions. In your normal cycle 9.8 critical 3.5% 2017-09-14
CVE-2017-13004 The Juniper protocols parser in tcpdump before 4.9.2 has a buffer over-read in print-juniper.c:juniper_parse_header(). In your normal cycle 9.8 critical 3.5% 2017-09-14
CVE-2017-13024 The IPv6 mobility parser in tcpdump before 4.9.2 has a buffer over-read in print-mobility.c:mobility_opt_print(). In your normal cycle 9.8 critical 3.5% 2017-09-14
CVE-2019-6798 An issue was discovered in phpMyAdmin before 4.8.5. A vulnerability was reported where a specially crafted username can be used to trigger a SQL injec… In your normal cycle 9.8 critical 3.5% 2019-01-26
CVE-2020-5648 Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function included in the firmware of GT14 M… In your normal cycle 9.8 critical 3.5% 2020-11-06
CVE-2016-3504 Unspecified vulnerability in the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.1.7.0, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0, and 12.2.1.0.… In your normal cycle 9.8 critical 3.5% 2016-07-21
CVE-2021-45887 An issue was discovered in PONTON X/P Messenger before 3.11.2. Due to path traversal in private/SchemaSetUpload.do for uploaded ZIP files, an executab… In your normal cycle 9.8 critical 3.5% 2022-03-13
CVE-2022-27270 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the c… In your normal cycle 9.8 critical 3.5% 2022-04-10
CVE-2022-27271 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the c… In your normal cycle 9.8 critical 3.5% 2022-04-10
CVE-2022-27272 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the f… In your normal cycle 9.8 critical 3.5% 2022-04-10
CVE-2022-27273 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the f… In your normal cycle 9.8 critical 3.5% 2022-04-10
CVE-2022-27274 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the f… In your normal cycle 9.8 critical 3.5% 2022-04-10
CVE-2022-27275 InHand Networks InRouter 900 Industrial 4G Router before v1.0.0.r11700 was discovered to contain a remote code execution (RCE) vulnerability via the f… In your normal cycle 9.8 critical 3.5% 2022-04-10
CVE-2026-0755 gemini-mcp-tool execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code… In your normal cycle 9.8 critical 3.5% 2026-01-23
CVE-2021-25770 In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution. In your normal cycle 9.8 critical 3.5% 2021-02-03
CVE-2023-30400 An issue was discovered in Anyka Microelectronics AK3918EV300 MCU v18. A command injection vulnerability in the network configuration script within th… In your normal cycle 9.8 critical 3.5% 2023-06-07
CVE-2022-42490 Several OS command injection vulnerabilities exist in the m2m binary of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network reques… In your normal cycle 9.8 critical 3.5% 2023-01-26
CVE-2021-46013 An unrestricted file upload vulnerability exists in Sourcecodester Free school management software 1.0. An attacker can leverage this vulnerability to… In your normal cycle 9.8 critical 3.5% 2022-01-18
← previous page 257 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt